

Dive into CFF font and coincidently learn about a bof in cff parsing from some jailbreak. just for fun


UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.

Proof-of-concept exploit for a heap over-read in libarchive RAR v4 filter (CVE-2025-5915) with ASan reproduction, encoder, and on-device iOS 18.5…

CVE-2026-43813: CloudAttestation enforceEnvironment bypass

Extraction of iMessage Data via XSS

A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)

Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)


iOS Syscall Explorer for IDA 9.X

Crash macOS and iOS devices with one packet


I do some tweaking for iOS from 16.0 to 16.1.2 based on MacDirtyCow (CVE-2022-46689) exploit.

Apple CoreGraphics framework fails to validate the input when parsing CCITT group 3 encoded data resulting in a heap overflow condition. A small heap…